CVE-2026-0654
Command injection on TP-Link Deco BE25
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper input handling in the administration web interface on TP-Link Deco BE25 v1.0 allows crafted input to be executed as part of an OS command. An authenticated adjacent attacker may execute arbitrary commands via crafted configuration file, impacting confidentiality, integrity and availability of the device. This issue affects Deco BE25 v1.0: through 1.1.1 Build 20250822.
| CWE | CWE-78 |
| Vendor | tp-link systems inc. |
| Product | deco be25 v1.0 |
| Published | Mar 2, 2026 |
| Last Updated | Mar 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for tp-link systems inc. deco be25 v1.0
Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. deco be25 v1.0 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
TP-Link Systems Inc. / Deco BE25 v1.0
0 โค 1.1.1 Build 20250822
References
Credits
caprinuxx